%% You should probably cite draft-ietf-anima-brski-ae or draft-ietf-anima-brski-prm instead of this I-D. @techreport{ietf-anima-brski-async-enroll-03, number = {draft-ietf-anima-brski-async-enroll-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-anima-brski-async-enroll/03/}, author = {Steffen Fries and Hendrik Brockhaus and Eliot Lear and Thomas Werner}, title = {{Support of asynchronous Enrollment in BRSKI (BRSKI-AE)}}, pagetotal = 60, year = 2021, month = jun, day = 24, abstract = {This document describes enhancements of bootstrapping a remote secure key infrastructure (BRSKI, {[}RFC8995{]} ) to also operate in domains featuring no or only timely limited connectivity between involved components. Further enhancements are provided to perform the BRSKI approach in environments, in which the role of the pledge changes from a client to a server . This changes the interaction model from a pledge-initiator-mode to a pledge-responder-mode. To support both use cases, BRSKI-AE relies on the exchange of authenticated self- contained objects (signature-wrapped objects) also for requesting and distributing of domain specific device certificates. The defined approach is agnostic regarding the utilized enrollment protocol allowing the application of existing and potentially new certificate management protocols.}, }